VendorsCandypresscandypress_store3.5.2.14
Vulnerabilities

Candypress Candypress Store 3.5.2.14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2006-6109
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
Published 2006-11-26 · Modified
7.52 PoCEPSS 0.014